Thoughts on cybersecurity mesh architecture (CSMA)? Is it just a new buzzword or a genuine step up from Zero Trust and SASE?

4.9k viewscircle icon1 Upvotecircle icon3 Comments
Sort by:
Director of Enablement2 years ago

Hot take: CSMA is SASE without a clear strategy.

SASE should focus on a convergence of technologies and vendor collapse to ensure consistent data context, while simplifying a typical chaos architecture.

CSMA typically takes point products and mashes them together with an overlay to help orchestrate each tier. What you end up with is generally a fragmented approach with a ton of kit you need to keep updated and patched.

CSMA is like a boat held together with duct tape. Sure it works, but you’re going to have to keep quite a few spare rolls on board if you want to sail

CTO in Software3 years ago

It all has its place. I am for knowing your assets, understanding your risks, then using defense in depth strategies to apply protections based on asset's value.

Sr. Director of Enterprise Security in Software3 years ago

The idea has a lot of merit. If you can consider your security strategy to be  puzzle pieces fitting together, rather than overlapping silos, there is much to be gained. Between better analytics, using "best in class" products specifically for their niche, and having the freedom to plug in solutions from various vendors, the idea seems really appealing on paper. I think it remains to be seen how the implementation will work, but much as we pushed for open APIs from vendors, having the ability to integrate your tools together to leverage them in a way that suits your use case the best, will be a market differentiator for a lot of products. 

Lightbulb on2

Content you might like

Yes, if followed correctly.39%

Unsure38%

No, there is still a significant risk.19%

Other (please tell us in the comments)3%

View Results

Yes65%

No35%